Security Overview
This page summarizes the current security posture of the DesignTech AI service based on the implemented application architecture and the managed service providers used in production.
Last updated: June 11, 2026
Production Stack
The baseline production stack currently includes Render for application hosting, Supabase for managed Postgres database services, Google Cloud Storage for file and media storage, and Google Cloud / Vertex AI for AI model execution. Search and content indexing run natively in Postgres (full-text and trigram), with no third-party search service. Each managed-provider name links to that provider's public trust center.
Authentication and Access Control
The application uses Auth0-backed authentication in production when configured and resolves authenticated users into application-level roles.
The platform implements role-based access controls, including super admin, organization admin, and user roles, with organization scoping enforced through the application and storage layers.
Development-only fallback login behavior exists in the codebase for local environments when Auth0 is not configured and should not be enabled for production customer environments.
Trust centers:
Logging and Data Protection
The service records audit signals for selected user and administrative actions and supports detailed execution payload logging for certain AI operations.
In the current implementation, detailed full execution payload logs are retained for 60 minutes by default and are subject to redaction logic for common secret patterns.
This page should not be interpreted as a commitment to any universal log-retention period beyond the current documented implementation.
AI Routing and Model Processing
Current application code sends AI requests directly to Google Vertex AI, including Gemini models and Anthropic Claude models served through Vertex AI. There is no third-party AI request-routing intermediary in the request path.
Model execution therefore runs on Google Cloud infrastructure under that provider's data processing terms.
This page does not state that all AI processing occurs only in the EEA or only on DesignTech AI-managed infrastructure.
Trust centers:
Versioning and Recovery Aids
The platform includes content versioning and per-section asset versioning for relevant objects. Those features support review, rollback, and operational recovery for specific content and asset workflows.
Incident Handling
Security incidents affecting customer data should be handled through documented internal processes, applicable provider processes, and contractual notification obligations.
This overview does not claim the existence of a dedicated 24/7 internal SOC, a fixed notification window, or any certification held by DesignTech AI unless separately evidenced.
Vulnerability Reporting
Security questions or vulnerability reports may be directed to: